Skip to content

Repository files navigation

🔐 Penetration Testing Labs

This repository contains my hands-on penetration testing practice labs based on real-world attack methodology and the Cyber Kill Chain model.


🎯 Objective

To simulate real-world attacks in a controlled lab environment and document reconnaissance, exploitation, and defense techniques.


🧠 Methodology: Cyber Kill Chain

1️⃣ Reconnaissance

  • Information Gathering
  • Nmap Scanning
  • Whois Lookup
  • DNS Enumeration

Tools Used:

  • Nmap
  • Whois
  • theHarvester

Screenshots: (Insert images here)


2️⃣ Scanning & Enumeration

  • Port scanning
  • Service version detection
  • SMB enumeration
  • Directory brute forcing

Tools Used:

  • Nmap
  • enum4linux
  • Gobuster

3️⃣ Exploitation

  • Vulnerability identification
  • Metasploit exploitation
  • Web app attacks (SQLi / XSS)

Tools Used:

  • Metasploit
  • Burp Suite

4️⃣ Post-Exploitation

  • Privilege escalation
  • Persistence
  • Data extraction

Tools Used:

  • Linux commands
  • Meterpreter

🛠️ Lab Environment

  • Kali Linux (Attacker)
  • Metasploitable 2 (Target)
  • VirtualBox

📚 What I Learned

  • Understanding attack flow
  • Identifying weak services
  • Practical exploitation workflow
  • Defensive thinking from attacker perspective

About

Hands-on penetration testing labs covering reconnaissance, enumeration, exploitation & post-exploitation based on the Cyber Kill Chain methodology.

Topics

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors